Enabling And Configuring Port Security - Cisco Catalyst 2950 Software Configuration Manual

Hide thumbs Also See for Catalyst 2950:
Table of Contents

Advertisement

Chapter 21
Configuring Port-Based Traffic Control
Table 21-3
Table 21-3
Type of Port
DTP
Trunk port
Dynamic-access port
SPAN source port
SPAN destination port
EtherChannel
Protected port
IEEE 802.1x port
Voice VLAN port
1. DTP = Dynamic Trunking Protocol
2. A port configured with the switchport mode dynamic interface configuration command.
3. A VLAN Query Protocol (VQP) port configured with the switchport access vlan dynamic interface
4. You must set the maximum allowed secure addresses on the port to two plus the maximum

Enabling and Configuring Port Security

Beginning in privileged EXEC mode, follow these steps to restrict input to an interface by limiting and
identifying MAC addresses of the stations allowed to access the port:
Command
Step 1
configure terminal
Step 2
interface interface-id
Step 3
switchport mode access
Step 4
switchport port-security
Step 5
switchport port-security maximum
value
78-11380-12
When a voice VLAN is configured on a secure port that is also configured as a sticky secure port,
all addresses seen on the voice VLAN are learned as dynamic secure addresses, and all addresses
seen on the access VLAN (to which the port belongs) are learned as sticky secure addresses.
You cannot configure port security on a per-VLAN basis.
The switch does not support port security aging of sticky secure MAC addresses.
The protect and restrict options cannot be simultaneously enabled on an interface.
summarizes port security compatibility with other features configured on a port.
Port Security Compatibility with Other Catalyst 2950 and 2955 Features
1
2
port
3
4
configuration command.
number of secure addresses allowed on the access VLAN.
Compatible with Port Security
No
No
No
Yes
No
No
Yes
Yes
Yes
Purpose
Enter global configuration mode.
Specify the interface to configure, and enter interface configuration
mode.
Set the interface mode as access; an interface in the default mode
(dynamic desirable) cannot be configured as a secure port.
Enable port security on the interface.
(Optional) Set the maximum number of secure MAC addresses for the
interface. The range is 1 to 132; the default is 1.
Catalyst 2950 and Catalyst 2955 Switch Software Configuration Guide
Configuring Port Security
21-9

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 2955

Table of Contents